Pamzey's vulnerability footprint centers on a patient queue-management system deployed in healthcare settings, a focused but prominent product within its specialized vertical. Vulnerabilities affecting the vendor skew toward serious outcomes and cluster around input-handling and authorization flaws—including code injection, cross-site scripting, SQL injection, and broader injection variants—that are characteristic of web-facing applications handling sensitive data. Defenders should treat updates to this product as high-priority given its healthcare context and the severity tendency of its disclosures; live exploitation and severity counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Pamzey over time
Signals from CVEs in this vendor scope (14 CVEs).
14 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-13122CRITICAL A vulnerability was detected in SourceCodester Patients Waiting Area Queue Management System 1.0. The affected element is the function getPatientAppointment of the file /php/api_pa | Nov 13, 2025 | 9.8 | 34 | NO | NO |
CVE-2025-13248CRITICAL A weakness has been identified in SourceCodester Patients Waiting Area Queue Management System 1.0. The impacted element is an unknown function of the file /php/api_patient_schedul | Nov 16, 2025 | 9.8 | 32 | NO | NO |
CVE-2025-64081CRITICAL SQL injection vulnerability in /php/api_patient_schedule.php in SourceCodester Patients Waiting Area Queue Management System v1 allows attackers to execute arbitrary SQL commands v | Dec 8, 2025 | 9.8 | 30 | NO | NO |
CVE-2026-3724HIGH A weakness has been identified in SourceCodester Patients Waiting Area Queue Management System 1.0. This impacts an unknown function of the file /checkin.php. This manipulation of | Mar 8, 2026 | 8.8 | 25 | NO | NO |
CVE-2026-1147MEDIUM A vulnerability was found in SourceCodester/Patrick Mvuma Patients Waiting Area Queue Management System 1.0. This affects an unknown part of the file /php/api_patient_schedule.php. | Jan 19, 2026 | 5.4 | 23 | NO | NO |
CVE-2026-2150MEDIUM A flaw has been found in SourceCodester/Patrick Mvuma Patients Waiting Area Queue Management System 1.0. Affected by this issue is some unknown functionality of the file /checkin.p | Feb 8, 2026 | 6.1 | 22 | NO | NO |
CVE-2026-1148MEDIUM A vulnerability was determined in SourceCodester/Patrick Mvuma Patients Waiting Area Queue Management System 1.0. This vulnerability affects unknown code. Executing a manipulation | Jan 19, 2026 | 6.5 | 22 | NO | NO |
CVE-2025-63718MEDIUM A SQL injection vulnerability exists in the SourceCodester PQMS (Patient Queue Management System) 1.0 in the api_patient_schedule.php endpoint. The appointmentID parameter is not p | Nov 7, 2025 | 6.5 | 22 | NO | NO |
CVE-2026-2149MEDIUM A vulnerability was detected in SourceCodester/Patrick Mvuma Patients Waiting Area Queue Management System 1.0. Affected by this vulnerability is an unknown functionality of the fi | Feb 8, 2026 | 6.1 | 21 | NO | NO |
CVE-2026-3817MEDIUM A vulnerability was detected in SourceCodester Patients Waiting Area Queue Management System 1.0. This issue affects some unknown processing of the file /patient-search.php. The ma | Mar 9, 2026 | 5.3 | 20 | NO | NO |
Signals from CVEs in this vendor scope (14 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Pamzey.
Media articles that mention a CVE ID that affects a product developed by Pamzey — matched by CVE ID, not by vendor name.